netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
Bypasses token redaction in NetLicensing, allowing authenticated clients to recover plaintext API key values

5 CRIT · 1 LOW · THREAT RED · 6 items · Generated in 168s
Bypasses token redaction in NetLicensing, allowing authenticated clients to recover plaintext API key values
No authentication or origin validation on MCP SSE transport
dbt platform tokens leaked due to unauthenticated OAuth endpoint
Unescaped locator data XSS in MCP-UI Resource allows attackers to inject arbitrary HTML and JavaScript, leading to unauthorized tool execution.
MCP server vulnerable to DNS-resolved Private Hostname SSRF, allowing exfiltration of sensitive data
Exposes Uni-CLI to local attacks if legacy HTTP transport is used without proper validation
No new AI-centered threat headlines found.